Privacy notice

What this notice covers

This notice explains what happens to your personal data when you use this site: the pay calculator, the worker profile form, the company request form, the request for contractor's-liability (tilaajavastuu) documents, your own page after you sign in, and the e-mails we exchange afterwards. It is written to meet Article 13 of the General Data Protection Regulation (GDPR) and section 4 of the Finnish Act on the Protection of Privacy in Working Life (759/2004), which applies to job applicants as well as to employees.

Short version. The calculator sends nothing anywhere. A profile you send is used for the recruitment process you take part in; after it ends we keep only the evidence needed to answer possible claims about that recruitment, generally for up to two years, in a separate archive. The talent pool is a separate choice, based on your consent, for 12 months at a time; the monthly update on sites and vacancies is another separate choice with its own unsubscribe. Signing in to your own page needs no password and no account: we e-mail you a link that works once, and it sets one cookie. No recruitment decision about you is made solely by a machine. You can see, correct or delete your data on your own page or by writing to [email protected]; quoting your application ID helps us find your record faster but is not a condition.

Who is responsible for your data (controller)

Who is responsible for your data (controller)
ItemDetails
ControllerGene-Works Oy, a company registered in Finland
Business ID (Y-tunnus)2198820-6
Registered addressTommolankatu 9, c/o Prismakeskus, 45130 Kouvola, Finland
Contact for data protection matters[email protected] — subject line "Privacy". We have not appointed a separate data protection officer; the same address reaches the people who handle your data.
Supervisory authorityOffice of the Data Protection Ombudsman, Finland (tietosuojavaltuutettu), tietosuoja.fi
Version of this notice26 September 2026 — checked against the sources listed at the end; legal review pending

The calculator — nothing leaves your browser

The pay calculator runs entirely in your browser. Your answers (trade, the description of the work you can do, shift, hours, tax percentage, basis for the right to work) and the result are not sent to us and are not stored on our side. You do not need to give a name or an e-mail address to see a result.

Only if you press "Send my profile" is a snapshot of the calculation (your answers, the pay-group range, the rates and the version of the rate tables) attached to your profile form — so that we check your case against the same numbers you saw. Until you send the form, the snapshot exists only in your browser's session storage and disappears when you close the tab. Details: Cookies.

Where your data is stored

When you send a form, the site writes it to Cloudflare Workers KV — a key-value store operated by our hosting provider. The record is encrypted at rest and replicated inside Cloudflare's own network, which means copies may sit outside the EU. Cloudflare acts as our processor under its data-processing agreement. Moving this storage to one whose jurisdiction is the EU is planned; until that is done, this page says plainly where your data actually is rather than implying an EU-only setup.

Alongside the record, the site writes the messages that have to go out — your confirmation and the internal card for our mailbox — into a queue. Our own server in Finland reads that queue once a minute, sends the e-mails and deletes the queue entry. The e-mail and messaging keys live only on that server: the site itself holds no keys for sending anything, which is why it cannot send you anything by itself.

What the site never stores: files of any kind (the forms refuse them) and your name — the worker form does not ask for one. Your IP address is processed to protect the forms: the site derives a pseudonymous identifier from it for the per-hour abuse counters, which expire by themselves within two hours. That identifier is not written into your application record. A pseudonymous identifier derived from an address is still personal data, and we treat it as such.

What we process, why, on what basis and for how long

What we process, why, on what basis and for how long
DataPurposeLegal basisRetention
Worker profile — trade; experience band; country of residence; basis for the right to work in Finland (and, if you give it, permit type and validity); e-mail; optionally phone or Telegram, preferred language of communication, earliest start month, rotation preference, English level; the calculation snapshot; the language of the page; the campaign tag (UTM) if you came from an advertisement; your application ID and the time of sendingTo assess whether we can offer you construction work in Finland, to contact you for a short call, to prepare a written offer when a site needs your trade, to show you your own page, and to keep a record of what we told you and when. Which fields are required and why is stated on the form itself; without the required fields we cannot assess the profile.Steps at your request before a possible employment contract (GDPR Art. 6(1)(b)); the employer's legal duty to verify the right to work of foreign employees (Aliens Act 301/2004, GDPR Art. 6(1)(c)); only directly necessary data is collected (Act 759/2004, section 3)Used for the recruitment process you take part in. After it ends we keep only the evidence necessary to establish, exercise or defend possible legal claims about that recruitment (GDPR Art. 17(3)(e)), generally for up to two years, in a separate archive with restricted access; the Data Protection Ombudsman accepted two years in a comparable case (decision 13.8.2020, case 6652/154/19). Then deleted. This is separate from the optional talent pool.
Talent pool — the same profile, kept after the selection process for future sitesTo keep you in our pool of candidates after the current process and to contact you individually about suitable rolesYour consent (GDPR Art. 6(1)(a)) — a separate, unticked box on the form. You can withdraw at any time; withdrawing does not affect anything done before, and does not by itself remove you from the monthly update, which is a separate choice12 months from your consent. Towards the end of that period we ask you to confirm that you still want to stay; without your confirmation the profile leaves the pool. A new selection process does not extend this consent by itself.
Monthly update — your e-mail address and page languageTo e-mail you one short update a month about sites and vacanciesYour consent (GDPR Art. 6(1)(a)) — a separate, unticked box, independent of the talent pool; prior consent is required for electronic direct marketing to a person (Act 917/2014, section 200)Until you unsubscribe — every update carries a one-click unsubscribe. Leaving the update does not remove you from the talent pool, and the other way round.
Right-to-work records — after we hire you: the basis of your right to work and its validity, and the documents showing it (passport or ID, residence permit card)Legal duty of the employer to verify the right to work and to keep the basis available for the occupational safety authorityAliens Act 301/2004 (chapter 5, employer's duties); GDPR Art. 6(1)(c)2 years after the end of the employment relationship. These documents are never asked for on this site — only by invitation, for a specific site, after we have spoken with you.
Company enquiry — company name, Business ID, contact name, work e-mail, phone, what you need (trades, headcount, site or city, start date, duration, rotation), your messageTo reply (our target is one Finnish working day), to prepare an offer, to open your client page and to keep the correspondenceSteps at your request before a possible contract (GDPR Art. 6(1)(b)); our legitimate interest in answering business enquiries (Art. 6(1)(f))24 months from the last message in the exchange, for an enquiry that leads to no contract (Gene-Works' retention policy adopted on 26 September 2026). Where a contract follows, the records tied to it are kept for as long as that contract and the duties arising from it require.
Request for tilaajavastuu documents — company name, Business ID, work e-mailTo send you our contractor's-liability document package and to record which version was sent to whom and whenOur legitimate interest in running our own document process and keeping a log of what was handed to whom (GDPR Art. 6(1)(f)); the client's duty to obtain the documents before concluding the contract follows from Act 1233/2006, sections 5–5aA log of which package version was sent, to whom and when, for as long as the client relationship it belongs to lasts and 2 years after the contracted work ends — the client's own retention duty under Act 1233/2006, section 5, is the client's, not transferred to us. 24 months when no contract follows (Gene-Works' retention policy adopted on 26 September 2026).
Sign-in link and session — the one-time link we e-mail you, and the session it creates: which record it opens, when it was created, when it expires, and the first characters of the link it came fromTo let you into your own page without a password or an account, and to keep you signed in on that device until you log outNecessary to provide the service you asked for (GDPR Art. 6(1)(b)); the cookie itself is strictly necessary under section 205 of the Act on Electronic Communications Services 917/2014, so it needs no consentThe link works once and expires after 30 days. The session expires 30 days after you use the link, or immediately when you log out. Neither record holds your IP address. See Cookies.
Access journal — today: your sign-in sessions and the delivery records of our messages. Planned: one line for every time one of our staff opens a record (the record ID, the time, who did it, the action) — never the content and never your IP addressSo that we can answer "who has seen my file?", and so that an authority can be shown who had accessOur duty as controller to process data securely and to be able to demonstrate it (GDPR Art. 5(1)(f), 5(2), 32) and our legitimate interest in the security of the service (Art. 6(1)(f))Sessions and delivery records expire on their own after 30 days. The planned staff-access journal will be held to a 12-month ceiling (Gene-Works' retention policy adopted on 26 September 2026); it is described here as planned because it is not switched on yet.
Abuse brakes — a hidden timestamp set when the form loads, an empty hidden field, an idempotency marker for the form you sent, and per-hour counters keyed to a pseudonymous identifier derived from your IP addressTo reject submissions filled in by robots, to keep one press of the button from creating two applications, and to slow down floodingOur legitimate interest in keeping the forms usable and the service available (GDPR Art. 6(1)(f))The counters live 2 hours and the idempotency marker 24 hours, then they expire by themselves. The identifier is not copied into your application record. It is derived from your address by a one-way function, but it remains personal data and is handled as such.
Technical data — your IP address and browser type, processed by our hosting provider to deliver the pages and protect the siteDelivering the site; protection against attacksLegitimate interest of the hosting provider and ours (GDPR Art. 6(1)(f))Processed by the hosting provider under its own retention rules for request logs; we do not receive it as a log of our own. Page-view statistics, if we ever switch them on, reach us only aggregated and without cookies — see Cookies.

Swipe the table sideways on a phone.

What we do not ask — and why

Finnish law allows an employer to process only data that is directly necessary for the employment relationship (Act 759/2004, section 3), and consent does not make extra questions lawful — so the initial form does not have them. In the initial form we do not ask for your name, date of birth, gender, family situation, health, religion, union membership, personal identity code, home address, nationality, photo, bank account or any files. Some of these become lawfully necessary later — for example your name and identity for an employment contract, or the details a site's main contractor must record by law — and we ask for them only at that step, for that purpose.

We ask for your basis for working in Finland for the proposed duties because the employer must verify the right to work by law; a permit or status from another EU country does not by itself give a right to work in Finland. This is a question about legal status, and pay-group classification is never based on nationality or origin (Non-discrimination Act 1325/2014, section 8). We collect your data from you only. We do not search social media or other sources about you. If we ever need information from another source for a specific step, we ask for your consent first unless the law provides otherwise (Act 759/2004, section 4).

Who receives your data (recipients and processors)

Who receives your data (recipients and processors)
RecipientWhat they getWhereRole
Our recruitment team at Gene-Works OyYour profile and the correspondenceFinlandController — the people who handle your profile
Our own server at Gene-Works OyIt reads the queue of messages to send, delivers them and keeps the working records of applications, statuses and assignments. The keys for e-mail and messaging live only hereFinlandController's own system
Our e-mail provider — the mailbox [email protected]The e-mails you send us and the internal cards delivered to that mailboxUnder the provider's terms for business mailboxes; named in full at legal reviewProcessor
Cloudflare, Inc. — hosting of the pages, the form endpoints and the Workers KV store behind themTechnical request data, and the record itself: your application is stored in Workers KV, encrypted at rest, for as long as the record is kept. Cookieless page statistics, if we switch them onServed and stored inside Cloudflare's own network, which replicates across regions, so processing and copies occur outside the EEA; this covers the application record, the message queue and support access. Under Cloudflare's customer data-processing agreement, which provides the EU standard contractual clauses and states participation in the EU–US Data Privacy Framework. Restricting durable storage to an EU jurisdiction is planned; it would not by itself end all processing outside the EEAProcessor
Resend (Plus Five Five, Inc.) — delivery of the e-mails our server sendsRecipient addresses, message content, sign-in links and delivery data of each message: your confirmation, your sign-in link and the internal card addressed to our own mailbox. The internal card contains the profile fields you sentThe sending region (EU, eu-west-1) determines routing, not storage: according to the provider's public documentation, customer data including message content and delivery logs is stored in the United States, normally for 30 days. Its public data-processing agreement provides the EU standard contractual clauses (module 2) and states participation in the EU–US Data Privacy Framework; that this agreement is in force for our account is being confirmed at legal reviewProcessor
Telegram — switched offNot in use. A notification to our own staff through Telegram was planned; it is switched off until a lawful basis for that transfer is documented, because even a line with only an application ID, a trade and a country is pseudonymous data that we can link to youNot applicable while switched offNot in use
A client company (user company, käyttäjäyritys) — only when we propose you for a specific site, and you know about itWhat the client needs for its own legal duties: your reference, trade, site and period, and the state of each requirement with its basis and check date — through the client page. Where the client is the site's main contractor, the law separately requires it to record your name, date of birth and tax number in the site's list of workers (Act 738/2002, section 52b); that is a separate, legally required disclosure and is handled outside the client page. Never your passport copy, tax card, bank details, net pay or health data through the client page — see Data and confidentialityFinlandIndependent controller for the data it receives
Occupational safety authority (työsuojelu — from 1 January 2026 the Finnish Supervisory Agency, Lupa- ja valvontavirasto) and other authoritiesWhat the law entitles them to on request — contracts, collective-agreement classification, hours, payslips, right-to-work basisFinlandAuthority

Swipe the table sideways on a phone.

We do not sell or rent your data, we do not use it for advertising, and we pass nothing to a client company before you know about it. Every processor works on our written instructions and only for the purposes in the table above.

Transfers outside the EU and EEA

Two services in the list above process data outside the European Economic Area. Cloudflare Workers KV replicates your record, the message queue and related processing inside Cloudflare's own network, so copies sit in regions outside the EEA. Resend stores the e-mails it delivers for us — including their content — in the United States.

Chapter V of the GDPR requires a safeguard for each such transfer. For both providers the safeguard is the EU standard contractual clauses incorporated into their customer data-processing agreements; both providers also state participation in the EU–US Data Privacy Framework, under the European Commission's adequacy decision for certified organisations. Whether each agreement is in force for our own account, and the providers' current certification status, are being documented at legal review; until that is done we describe the mechanism as the providers publish it. Copies of the applicable safeguards are available on request at [email protected].

Telegram is not used: the planned staff notification through it is switched off until a lawful basis for that transfer is documented.

Your own page — signing in, and the one cookie

There is no password and no account to create. When you want to open your page, you ask for a link to the e-mail address you used; we send a link that works once and expires after 30 days. Using it creates a session and sets one cookie, gw_session, for 30 days on that device. The cookie holds nothing but a random value: no name, no e-mail, no pay figure. It is strictly necessary for the page you asked for (Act 917/2014, section 205), so there is no banner to click; the 30-day life of the link and of the session is our own setting, not a period set by law. The site sets no analytics or advertising cookies. Full list: Cookies.

The sign-in page answers the same way whether or not we know the address you typed: the answer "we have sent a link" would otherwise tell anyone whether a given person had applied. A link for a worker's page never opens a client's page and the other way round. Log out and the session is deleted on our side, not just in your browser.

What your page shows today: your application as we received it, its status, the consents you gave, each requirement for working on a Finnish site with its own state — verified, pending, missing, or "for review" when nobody has checked yet — and your pay ledger once there is one. It does not show our internal correspondence or notes; those you can request by e-mail. We would rather show you a grey "for review" than a reassuring green.

Three views — and what a client never sees

The same facts are shown differently to three parties: to you, in full on your page; to the client company that directs your work on its site, only what it needs for its own legal duties; and to the occupational safety authority, what the law lets it ask for. Through the client page a client never sees a copy of your passport or permit, your tax card or tax percentage, your net pay, your bank account, deductions ordered by an authority, or your family situation. Health information is not displayed in the client page; any legally necessary information about work restrictions is handled separately and disclosed only on a verified legal basis. Consent or a commercial contract does not remove the requirements of necessity, confidentiality and a valid legal basis. Disclosures that a specific law requires — such as the site list kept by a main contractor — are made on that basis and are listed separately. The whole table is on Data and confidentiality.

No automated decisions

The calculator is guidance, not a decision. It shows a preliminary pay-group comparison based on your answers and the published collective-agreement tables; the group, the rate and all terms are approved by a person after checking your documents and skills, and only in a written offer. Where your answers do not match any description of work in the agreement, the calculator deliberately shows no figure at all and offers you a manual assessment instead. We do not make recruitment decisions based solely on automated processing that produce legal or similarly significant effects on you (GDPR Art. 22).

Your rights and how to use them

You have the right to access the data we hold about you, to have it corrected, to have it deleted, to restrict processing, to object to processing based on our legitimate interest — and an objection to direct marketing is always honoured — to receive the data you gave us in a machine-readable form where processing rests on your consent or a contract and is automated, and to withdraw a consent at any time. Withdrawing consent does not affect what was done before it.

How, in practice. Open your own page with the link from your confirmation e-mail: it shows your application, its status, your consents and the state of each requirement, and carries a button that asks us to delete your data. Or write to [email protected] from the e-mail address you used on the form; quoting your application ID (GW-2026-…) helps us find your record but is not a condition. Either way a person answers, without undue delay and within one month of receipt (GDPR Art. 12(3)); in a complex case we may extend by up to two further months and tell you why within the first month. Every talent-pool e-mail carries a link to leave the pool, and every monthly update a link to unsubscribe.

Deletion has limits, and we name them instead of hiding them: the right-to-work records of an employee (Aliens Act 301/2004, section 82, two years after the employment ends); the minimum evidence needed to answer possible claims about a recruitment you took part in, generally for up to two years (GDPR Art. 17(3)(e)); the log of a document package sent to a client. In each case we tell you what is kept and until when. A deletion request is registered immediately and carried out by a person; nothing is silently dropped in the meantime.

If you think we handle your data unlawfully, you can complain to the Office of the Data Protection Ombudsman (tietosuojavaltuutettu), tietosuoja.fi. We would like to hear from you first, but that is not a condition.

Security

The site is served over an encrypted connection and the store behind it is encrypted at rest. Your profile is handled by our recruitment team. Sign-in links are single-use; the session cookie is marked HttpOnly, Secure and SameSite=Lax, so no script on the page can read it and it is not sent with cross-site requests other than top-level navigation. Of your IP address the forms keep a short-lived pseudonymous identifier for abuse counters, not a log of where people write from.

We never charge workers recruitment or placement fees, deposits or related service charges, and we do not retain original passports. Documents proving your right to work are requested by invitation, for a specific site, into a protected store — not through this site's forms and not by chat. Every message from us comes from an @geneworks.fi address; if a message does not, do not answer it — forward it to [email protected].

Common questions

Does the calculator store anything about me?

No. Everything happens in your browser. Only if you press "Send my profile" is the calculation attached to your form, and until then it sits in your browser's session storage and disappears when you close the tab.

My application is in a store that replicates outside the EU. Why?

Because that is what the hosting platform we start on offers, and saying so is better than implying an EU-only setup. The record is encrypted at rest, it stays inside the provider's own network under a data-processing agreement, and a move to a store whose jurisdiction is the EU is planned. When it happens, this page changes with a new version date.

I sent a profile but did not tick the talent-pool box. What happens to it?

It is used for the current selection process. After that process ends we keep only the evidence needed to answer possible claims about it, generally for up to two years, in a separate archive; the rest is deleted. You will not be contacted about future roles and you will not receive the monthly update.

Do I need a password for my page?

No. You ask for a link to your e-mail address; it works once and sets one strictly necessary cookie for 30 days. There is no account, no password to lose and no third-party login.

Will a client see my passport, tax card or how much I take home?

No. A client sees what it needs for its own legal duties — your reference, trade, site, period and the state of each requirement with its basis and date. Details: Data and confidentiality.

How do I delete my data?

Use the button on your own page, or write to [email protected] from the address you used; your application ID helps but is not required. We confirm what was deleted and what, if anything, we must keep and until when.

Do you use my e-mail for advertising?

Not without your separate consent. You receive a confirmation, your sign-in link and messages about your own selection process. The monthly update about sites and vacancies goes only to people who ticked that separate box, and every update carries a one-click unsubscribe.

Sources this notice relies on

GDPR Articles 5, 6, 12–22, 32 and Chapter V · Act on the Protection of Privacy in Working Life 759/2004, sections 2–4 · Aliens Act 301/2004, section 82 (employer's duties and the two-year record) · Non-discrimination Act 1325/2014, sections 8, 12–13 and 17 · Act on the Contractor's Obligations and Liability 1233/2006, sections 4–5a and 7 · Occupational Safety and Health Act 738/2002, sections 52a–52b · Act on Electronic Communications Services 917/2014, sections 200 and 205, and the Traficom cookie guidance (in force from 13 September 2021) · Decision of the Data Protection Ombudsman of 13 August 2020, case 6652/154/19, on the retention of applicant data · Resend and Cloudflare public data-processing agreements. Checked against the source texts on 25–26 September 2026.

Privacy notice, version of 26 September 2026 (revised the same day after a legal pre-check) — written for the current architecture, where applications are stored in Cloudflare Workers KV and sent onward by our own server in Finland. Legal review pending. Changes to this notice are published on this page with a new version date.